Back

HIGH

HTML Forms < 1.3.25 - Admin+ SQLi

Published Nov 28, 2022

Description

The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Nov 28, 2022
Updated Apr 25, 2025
Reserved Oct 26, 2022
CISA Vulnrichment
Updated Apr 25, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a